Truebit loses $26M to exploit as old DeFi protocols targeted

Integer overflow exploit drains 8,535 ETH (~$26M) and ~$300K TRU from unaudited Truebit 2021 contract

  • Truebit lost 8,535 Ether (about $26 million) and nearly $300,000 in TRU tokens to a Hacker on Thursday.
  • The exploited smart contract was deployed in 2021 and has no public record of a third-party audit.
  • DeFi hacks have continued into 2025, with over $2.5 billion stolen, according to data.
  • Security researchers say attackers are increasingly targeting older, lightly maintained protocols.
  • The breach used an integer overflow vulnerability, a known “maths problem” in smart contracts, as noted by security posts.

On Thursday at about 4pm London time, a hacker drained 8,535 Ether — roughly $26 million — from the reserves of Truebit by exploiting a bug in a smart contract deployed in 2021. The attacker then took just under $300,000 of the protocol’s TRU token. Truebit acknowledged the breach and, it said, “We are in contact with law enforcement and taking all available measures to address the situation.”

- Advertisement -

The compromised contract has no public record of a third-party audit, and the protocol moved to flag the incident soon after it occurred. The attack adds to a larger pattern of losses across crypto in 2025; data shows attackers stole more than $2.5 billion from projects this year.

Security researchers note Hackers are focusing on older DeFi protocols. Balancer lost $128 million in November from a contract live since 2021. Other legacy victims include vaults from Yearn Finance, projects from Rari Capital, and Ribbon Finance. Research commentary highlights that many of these contracts were written before current best practices were widespread and are no longer actively maintained. See a researcher’s discussion on the trend here and a developer post linking the trend to AI use by attackers here.

The Truebit breach used an integer overflow flaw — a numeric wraparound that lets attackers bypass checks and alter balances — a point noted in security posts explaining the vector. Integer overflows remain a recurring issue; for example, a July exploit on Cetus involved the same class of bug and led to about $220 million in losses.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -

Latest News

STRC Sales Surge, Eye Record Single-Day Bitcoin Buy

A community dashboard tracking Strategy's STRC sales suggests March 12, 2026 could see the...

SEC’s Peirce Urges Simpler Rules Amid Tokenization Talks

SEC Commissioner Hester Peirce argues regulators should avoid micromanaging markets and consider simplifying disclosure...

Rust VENON Malware Targets Brazilian Banking Apps

A new Rust-based banking Trojan named VENON is targeting Brazilian users, departing from the...

Ethereum Holds $2K Amid ETF Inflows, Gains Across Timeframes

Ethereum (ETH) is holding above $2,000 despite a volatile market, showing gains across most...

OP Labs Lays Off 20 Staff as Optimism Focus Narrows

OP Labs, the core developer behind the Ethereum layer-2 Optimism network, has laid off...

Must Read

Buy Domain With Bitcoin: Top 8 Domain Registrars That Accept Bitcoin And Crypto

You are here because you want to buy a domain with bitcoin, right? If you are looking for domain registrars that accept bitcoin or...